Skip to content
Snippets Groups Projects
  1. Jun 30, 2020
  2. Apr 14, 2020
  3. Apr 02, 2020
  4. Mar 25, 2020
  5. Mar 09, 2020
  6. Feb 25, 2020
  7. Jan 23, 2020
  8. Dec 20, 2019
  9. Dec 02, 2019
  10. Nov 28, 2019
  11. Sep 20, 2019
  12. Aug 05, 2019
  13. Jun 13, 2019
  14. Apr 11, 2019
  15. Mar 12, 2019
  16. Mar 05, 2019
  17. Feb 25, 2019
  18. Feb 22, 2019
    • Vladimír Čunát's avatar
      daemon: rework handling of TLS authentication params · 81b1450e
      Vladimír Čunát authored and Petr Špaček's avatar Petr Špaček committed
      It's mainly about the way we parse and validate them.
      
      Almost all of the parts of validation that were being done
      in modules/policy/policy.lua and daemon/tls.c got moved
      to daemon/bindings/net.c, so it's easier to follow that.
      Also more checks are being done now, e.g. contents of .pin_sha256
      and .hostname strings.
      81b1450e
    • Vladimír Čunát's avatar
      policy.TLS_FORWARD: send SNI on wire if configured · a4284580
      Vladimír Čunát authored and Petr Špaček's avatar Petr Špaček committed
      In https world it's standard to do that, and it's relied on.
      Real-life example: 8.8.8.8#853 over TLSv1.3 won't send a certificate
      if we don't send SNI (no idea why; also they do send it with TLSv1.2).
      
      As a consequence, we no longer allow multiple hostnames per
      address-port tuple, but that didn't seem useful.
      a4284580
  19. Feb 06, 2019